CVE · Medium

CVE-2024-6455 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6455 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.2.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 3.2.1 3.2.1 2024-07-18

CVE-2024-6455

The ElementsKit Elementor addons plugin for WordPress contains an oversight that allows unauthorized access to sensitive content. In versions 3.2.0 and earlier, the ekit_widgetarea_content function lacks necessary permission checks, enabling unauthenticated users to view any item created with Elementor, including unpublished drafts and private content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.